Fake Pirated 'The Odyssey' Downloads Hide Crypto-Stealing Malware, Bitdefender Warns
Key Takeaways
- •Fake downloads of "The Odyssey" surfaced within days of the film's release, disguised as high-definition WEBRip and Blu-ray rips that were actually Windows executables carrying Lumma Stealer malware.
- •Lumma Stealer extracts browser passwords, payment details, autofill data, remote desktop credentials, and cryptocurrency wallets, and steals authentication cookies that can bypass multi-factor authentication.
- •Lumma has been rented out via a malware-as-a-service model since at least 2022, and after Microsoft and U.S. authorities seized roughly 2,300 of its domains in May 2025, its operators rebuilt their infrastructure.
- •The campaign mirrors a near-identical 2025 operation that distributed the same malware through fake "Mission: Impossible – The Final Reckoning" download files.
- •Bitdefender advises using legitimate streaming services, never running an executable advertised as a video, and enabling Windows file-extension display to expose disguised files.

Fake pirated copies of “The Odyssey” began circulating within days of the blockbuster’s release, disguised as high-definition movie rips but actually Windows executables that install crypto-stealing malware, according to security firm Bitdefender.
The malware also steals authentication cookies—allowing attackers to hijack accounts even with multi-factor authentication switched on—and hides behind VLC-style file icons. The case fits a broader pattern of wallet-draining malware riding in on desirable content.
Fans trying to grab an illicit copy of the film may end up handing over their crypto wallets instead. Bitdefender said this week that fake pirated downloads of the newly released blockbuster are already circulating loaded with Lumma Stealer, an information-stealing malware that hunts for cryptocurrency wallets among other sensitive data. Lumma—also tracked as LummaC2—has been rented out to attackers through a malware-as-a-service model on underground forums since at least 2022, giving even low-skilled operators access to industrial-grade theft tooling. Microsoft and U.S. authorities coordinated a takedown in May 2025 that seized control of roughly 2,300 Lumma domains, but security researchers subsequently observed its operators rebuilding infrastructure, a sign that disruption slows rather than stops this class of threat.
According to the company, the malicious files surfaced within days of the film’s launch, disguised as high-definition WEBRip and Blu-ray rips with names mimicking legitimate torrent releases. In reality, they are Windows executables that infect a machine rather than play a movie.
To sell the disguise, attackers often swap in icons resembling VLC Media Player or video files—a trick made more effective because Windows hides file extensions by default, leaving many users unable to tell an “.exe” from an actual video.
Fake downloads of The Odyssey are already being used to spread Lumma Stealer malware. This threat can steal passwords, browser cookies, and crypto wallets. See how Bitdefender Ultimate Security can help protect your digital life:
— Bitdefender (@Bitdefender) August 12, 2026
Once run, Lumma Stealer scrapes browser passwords, saved payment details, autofill data, remote desktop credentials and crypto wallets. It also lifts authentication cookies, meaning victims can lose access to their accounts even with multi-factor authentication switched on. The focus on crypto wallets is what makes stealers like Lumma especially damaging: blockchain transfers are irreversible, so funds siphoned from a drained wallet are rarely recovered.
Bitdefender said its products blocked the downloads and flagged command-and-control domains tied to the operation, and noted that the campaign mirrors a near-identical one in 2025 that hid the same malware inside fake “Mission: Impossible – The Final Reckoning” files.
The findings underscore how routinely attackers now bury wallet-draining code inside content people are eager to download. Over the years, there has been a steady drumbeat of similar schemes, including malware smuggled through fake CAPTCHA pages routed via BNB Chain, the SparkKitty campaign that slipped wallet-stealing code into mobile apps, and malicious “anime girl” wallpapers aimed at Steam gamers. Attackers have also poisoned developer tooling, planting crypto-stealing code inside a booby-trapped Python library.
The common thread is that the malware rides in on something the victim actively wants—whether a pirated film, a game mod or a coding package. Bitdefender’s advice is blunt: stick to legitimate streaming services, never run an executable advertised as a video, and enable Windows’ file-extension display so a disguised “.exe” cannot pass as a movie.